⚠️ Unpublished: This item is from a solution that is not yet published on Azure Marketplace or not installed in Content Hub.
Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊
| Attribute | Value |
|---|---|
| Connector ID | RedCanary_ConnectorDefinition |
| Publisher | Red Canary |
| Used in Solutions | Red Canary |
| Collection Method | CCF Push |
| Connector Definition Files | RedCanary_ConnectorDefinition.json |
| DCR Definition Files | RedCanary_DCR.json |
| CCF Configuration | RedCanary_dataconnector.json |
| CCF Capabilities | Push |
| Ingestion API | Log Ingestion API — CCF Push connectors use DCR-based Log Ingestion API |
| Custom Log V1 Tables | Yes 🔶 — ingests into tables with type-suffixed columns |
The Red Canary data connector enables Red Canary to publish detections into Microsoft Sentinel using the Codeless Connector Framework push pattern and the Azure Monitor Logs Ingestion API.
This connector ingests data into the following tables:
| Table | Transformations | Ingestion API | Lake-Only |
|---|---|---|---|
RedCanaryDetections_CL 🔶 |
? | ✓ | ? |
💡 Tip: Tables with Ingestion API support allow data ingestion via the Azure Monitor Data Collector API, which also enables custom transformations during ingestion.
Resource Provider Permissions:
Custom Permissions:
⚠️ Note: These instructions were automatically generated from the connector's user interface definition file using AI and may not be fully accurate. Please verify all configuration steps in the Microsoft Sentinel portal.
1. Create connector resources
Deploy the CCF push resources required for Red Canary detection ingestion.
Clicking Deploy creates the Log Analytics table, Data Collection Rule (DCR), Data Collection Endpoint (DCE), Microsoft Entra application, application secret, and role assignment required to ingest Red Canary detections through the Azure Monitor Logs Ingestion API. Deploy Red Canary connector resources
2. Configure Red Canary
Use the generated values to configure Red Canary to send detections to this Microsoft Sentinel workspace.
TenantIdNote: The value above is dynamically provided when these instructions are presented within Microsoft Sentinel.
ApplicationIdNote: The value above is dynamically provided when these instructions are presented within Microsoft Sentinel.
ApplicationSecretNote: The value above is dynamically provided when these instructions are presented within Microsoft Sentinel.
DataCollectionEndpointNote: The value above is dynamically provided when these instructions are presented within Microsoft Sentinel.
DataCollectionRuleIdNote: The value above is dynamically provided when these instructions are presented within Microsoft Sentinel.
Custom-RedCanaryDetections
Configure the Red Canary Microsoft Sentinel response action with the values above. Red Canary should post detection records to the Logs Ingestion API endpoint using the stream name Custom-RedCanaryDetections.📄 Source: [Red Canary\Data Connectors\README.md](https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Red Canary\Data Connectors\README.md)
This folder contains the Red Canary Codeless Connector Framework (CCF) push connector for Microsoft Sentinel. The connector creates the resources required for Red Canary to send detections to the RedCanaryDetections_CL table through the Azure Monitor Logs Ingestion API.
RedCanary_ccf/ - Connector definition, push connector resource, DCR, and table schema.After the solution is published, the connector is available in the Microsoft Sentinel data connectors gallery.
The connector shows data after Red Canary successfully posts detection records to the Logs Ingestion API.
For package validation, deploy the Red Canary solution package to a Microsoft Sentinel workspace and open the installed connector page. After deploying the connector resources, post a test JSON array to the Custom-RedCanaryDetections stream. The solution README includes the expected payload shape.
Confirm that:
RedCanaryDetections_CL.detection_id_s creates one alert and one incident.detection_id_s creates another raw row while the analytic rule continues to evaluate one representative record per detection ID in its query window.detection_id for up to seven days.Useful ingestion check:
RedCanaryDetections_CL
| where detection_id_s == "rc-detection-12345"
| summarize Rows=count(), FirstSeen=min(TimeGenerated), LastSeen=max(TimeGenerated) by detection_id_s
The solution README includes the payload contract, alert behavior, and validation queries.
Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊